# Rename filebeat default fields

**URL:** <https://discuss.elastic.co/t/rename-filebeat-default-fields/88002>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 1, 2017, 11:59pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002 "2017-06-01T23:59:44Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![filebeater](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/filebeater/32/18565_2.png) [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Post date:** [June 1, 2017, 11:59pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/1 "2017-06-01T23:59:44Z")

</div>

Is there a way for me to rename "beat.hostname" to "hostname" in filebeat output?

the documentation mentioned filter, but this seems like a filter setup in logstash, not in filebeat, right?  
per [https://www.elastic.co/guide/en/beats/filebeat/current/migration-changed-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/migration-changed-fields.html),  
I included the following in filebeat.yml, filebeat complained about the syntax "Exiting: error loading config file: yaml: line 71: could not find expected ':'"

```auto
filter {
    mutate {
        rename => {
            "filebeat.hostname" => "hostname"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 2, 2017, 2:20am UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/2 "2017-06-02T02:20:19Z")

</div>

> [@filebeater](#):
>
> Is there a way for me to rename "beat.hostname" to "hostname" in filebeat output?

It can be done using Logstash or using the [Ingest Node](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) feature in Elasticsearch.

> [@filebeater](#):
>
> the documentation mentioned filter, but this seems like a filter setup in logstash, not in filebeat, right?

Right, that is a Logstash filter example.

---

<div class="post-metadata">

**Author:** ![filebeater](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/filebeater/32/18565_2.png) [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Post date:** [June 2, 2017, 5:08pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/3 "2017-06-02T17:08:01Z")

</div>

Thanks for the clarification. that is a bummer, we would like to deploy filebeat only at the edge server, and remove those unnecessary fields before sending them out.

Btw, just to make sure I understand this, log stash is heavy weight, not supposed to deployed at the edge server (where our production service is running), right?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 2, 2017, 5:45pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/4 "2017-06-02T17:45:58Z")

</div>

> [@filebeater](#):
>
> and remove those unnecessary fields before sending them out.

You can remove the fields with Filebeat alone. You just cannot rename them.

```auto
processors:
- drop_fields:
    fields: ['beat.hostname']

```

With an ingest node pipeline in Elasticsearch you can rename the fields and this only requires Filebeat and Elasticsearch.

> [@filebeater](#):
>
> Btw, just to make sure I understand this, log stash is heavy weight, not supposed to deployed at the edge server (where our production service is running), right?

You could deploy LS on your edge nodes. It will likely have a larger memory footprint than Filebeat. If your only task is sending a logs then I would recommend Filebeat.

---

<div class="post-metadata">

**Author:** ![filebeater](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/filebeater/32/18565_2.png) [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Post date:** [June 2, 2017, 7:35pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/5 "2017-06-02T19:35:28Z")

</div>

> [@andrewkroh](#):
>
> rename

@andrewkroh is it possible to remove "@timestamp" and "type"?

thanks!  
yan

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 2, 2017, 7:54pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/6 "2017-06-02T19:54:36Z")

</div>

Those fields are protected from being removed because they are used by some of the outputs in beats. But you can drop them with the ingest node [remove](https://www.elastic.co/guide/en/elasticsearch/reference/master/remove-processor.html) processor.

---

<div class="post-metadata">

**Author:** ![filebeater](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/filebeater/32/18565_2.png) [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Post date:** [June 6, 2017, 10:48pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/7 "2017-06-06T22:48:03Z")

</div>

## I currently set up filebeat and logstash on the same machine in my local dev box, config filebeat to send output to logstash. In my logstash output, beat.hostname and host have the same value. I read the following in the filebeat documentation. I would like to confirm that host is indeed directly copied from beat.hostname, such that when i deploy filebeat and logstash on different servers, they would still have the same values and I can safely remove "beat" field in logstash filter. I would like to keep the hostname of the edge server where filebeat is located. Could someone please correct me if i mis-interpreted the following? If my understanding is correct, why duplicated fields are kept by default?

## Filebeat uses "beat.hostname" for Sending the Hostname of the Server. While the Logstash Forwarder sends the hostname of the server it’s running on in the host field, Filebeat uses the beat.hostname field for the same purpose. Because host is commonly used in the Logstash plugin ecosystem, the Beats input plugin automatically copies beat.hostname into host.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2017, 10:52pm UTC](https://discuss.elastic.co/t/rename-filebeat-default-fields/88002/8 "2017-07-04T22:52:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
